The Portable DevSecOps Control Plane for Modern Web Apps

Deploy faster. Secure honestly. Operate with confidence.

Deploy, secure, monitor, and connect your applications from one powerful platform. Manage reverse proxies, apps, Docker, certificates, WAF, Security Center, VPN mesh, and cluster operations without stitching together ten different tools. And it's the only tool in this category that throws in a real remote terminal and file manager across your whole device fleet - free, opt-in per device, fully audited - the kind of thing RMM vendors charge per-device every month for.

Download v{{VERSION}} Explore Features Getting Started
v{{VERSION}} · Security Center · .NET 8 · Windows 10/11 + Linux x64 · GUI ~222 MB (Full) / ~98 MB (Lite) · CLI ~27-40 MB
25
GUI Sidebar Views
20
REST API Endpoints
6
Starter Plugins
28
Compliance Controls
14
WAF Rules Built-in

Everything You Need

A complete development and production web stack that runs from any folder. No installation, no registry changes, no admin required.

🔒

TLS Termination & Reverse Proxy

Apache 2.4 reverse proxy with TLS 1.2/1.3, SNI multi-domain support, Let's Encrypt automation via bundled win-acme, self-signed cert generation with bundled OpenSSL. Auto-detects cert paths and generates vhost configs.

App Runner & Sub-Processes

Start, stop, and monitor backend apps with health checks, auto-restart on crash, and multi-stage sub-processes. Run Supabase + npm dev simultaneously. Auto-accept prompts for npx/npm commands. Per-app environment variables.

📦

Secure Project Import (Drag & Drop Deploy)

Drop a .zip/.7z project onto the Dashboard and ProxyStack extracts it, detects the stack — Node.js, Bun, Python, Go, .NET, Java, Ruby, PHP, Rust, Deno, Docker Compose, or a raw Dockerfile — and dry-runs executable stacks through the Process Reputation sandbox before ever presenting a command as trustworthy. Frontend builds can deploy as a static Site instead of a long-running process. Docker Compose imports get their own managed project tab with rollback, service status, profile/service selection, and logs. Auto Build shows a build plan, env-var guidance, and failure logs before you guess at fixes. Every import's full evidence trail is logged permanently.

🤖

AI Runtime Manager, Knowledge Base & Operator Assistant

Run local LLMs the same way you'd manage a Site or App: hardware scan, model recommendation from an 11-model hash-verified catalog, one-click llama.cpp/Ollama install, and a real local OpenAI-compatible server with Start/Stop/Restart, health checks, and an API key. Build a local RAG Knowledge Base from your own documents (PDF, DOCX, Markdown, text) and ask it questions with citations. Then ask the read-only AI Operator Assistant plain-language questions about your sites, apps, and security findings - it can explain, but it can never restart, reconfigure, or reveal a secret.

🐳

Docker & PostgreSQL

Full Docker container management with Compose up/down, image pull, container logs. Portable PostgreSQL with one-click auto-install and progress bar. Database console for direct SQL queries. Supabase health monitoring.

🛡

SentinelAI Integration

Connect to your SentinelAI dashboard for 25+ real-time security monitors, 3-stage ML threat detection (local ML → heuristics → AI), ransomware canary files, fleet management, and remote agent commands.

OWASP Compliance Dashboard

10 automated checks against the OWASP Top 10 2025. Security score 0–100 with pass/fail breakdown per category. Color-coded OWASP cards for A01 through A10. Export compliance reports as CSV or TXT.

🛡

Web Application Firewall (WAF)

14 built-in rules covering SQL injection, XSS, path traversal, command injection, SSRF, and more. Custom rule editor with regex patterns. Block-mode rules are enforced inline (real 403s, not just logging) whenever the pattern can be safely compiled into config, on both Nginx and Apache. Export as ModSecurity .conf for a separately installed ModSecurity module.

🔍

Security Scanner

Quick Scan (11 checks) and Full Scan (18 checks) covering TLS config, headers, directory permissions, secrets exposure, network ports, containers, database security, and more. Severity breakdown: Critical, High, Medium, Low. Async scanning with progress bar. Results persisted and exportable.

🔑

Secrets Vault Pro

DPAPI-encrypted key-value store (Windows CurrentUser scope). 8 categories: General, Database, API Key, OAuth, SSL/TLS, Cloud, Service, Internal. Reveal with 5-second auto-hide. Copy with 30-second clipboard auto-clear. One-click rotation with 32-char cryptographic random. Export as .env file. Backward compatible with legacy format.

📋

Compliance Reporting

4 frameworks: SOC2 Type II (9 controls), GDPR (6 articles), PCI-DSS v4.0 (8 requirements), HIPAA (5 safeguards). "All Frameworks" mode runs all 28 checks at once. Each check evaluates real config and provides evidence. Compliance score with pass/fail/N/A. Export as CSV or formatted TXT.

🔐

Zero Trust Security

mTLS (mutual TLS) toggle with CA certificate generation (RSA 4096-bit, 10yr) and server certificate generation (RSA 2048-bit, 2yr) with auto-SAN from configured domains. Certificate-based auth policies: CN, OU, Issuer, Fingerprint, SAN match. Network segmentation zones with CIDR, port, and direction rules. Trust score 0–100. Export Apache .conf with SSLVerifyClient and SSLRequire directives.

🛡

Security Center & Process Reputation

Unified status + threat timeline across WAF, SentinelAI, Cluster, Microsoft Defender, ClamAV, and Headscale VPN. Process Reputation monitors every ProxyStack-managed app's processes in real time - deterministic risk scoring, VirusTotal hash lookup, explicitly-gated sample submission, isolated low-privilege sandbox detonation, and policy enforcement (Kill/Quarantine/Block/Isolate/Approve), manual or fully automatic.

📈

Monitoring & Observability

Real-time CPU, RAM, and disk metrics. Real request rate and error rate parsed from live Nginx access logs. Latency percentiles shown when computable, honestly reported as unavailable otherwise - see Proof Status. Custom alert thresholds with email and Slack notifications.

👥

Team Collaboration

Multi-user RBAC with admin, editor, and viewer roles. Audit logging for all config changes. Share complete stack configs via .psxt templates (v1.1 bundles SSL certs as base64). Slack webhook notifications. Import creates missing site directories automatically.

🚀

Production Ready

Rate limiting per-IP and per-route (Nginx). Automated config backups with rotation. Load balancing across multiple backends. SSL certificate expiry monitoring via the Cert Expiry Notifier plugin. Remote management REST API for headless operation.

🔌

Integrations & Extensibility

REST API v2.0 with 20 endpoints for remote management. Real plugin runtime with 6 bundled starter plugins and a hosted marketplace for more. Multi-server cluster management with config sync, plus optional VPN mesh join. VS Code extension, CLI tool, 19 service blueprints (Next.js, Django, Flask, Express, etc.).

🔨

Advanced Features

Request/response rewriting with regex. HTTP caching layer with Redis support. API gateway with path-based versioning. Dark/light theme toggle. Auto-update system with SHA256 integrity verification and rollback. Classic UI mode via --classic flag.

🗂

Portable PostgreSQL

One-click PostgreSQL auto-install with progress bar. Start/stop/restart from the GUI. Database list, create/drop databases, and a built-in SQL query runner. No Docker required — runs as a portable binary from the postgres/ folder.

🔒

SSL Certificate Manager

Dedicated Certificates view for managing all SSL certs. Let's Encrypt automation via bundled win-acme (HTTP-01 validation). Self-signed cert generation via bundled OpenSSL. Auto-detect cert paths by domain name. Certificate expiry monitoring with alerts.

🛒

Plugin Marketplace

Real hook-based plugin runtime: 6 bundled starter plugins (Uptime Pinger, Cert Expiry Notifier, Deploy Webhook Notifier, Brute-Force IP Blocker, Config Git History, Daily Ops Digest), all disabled by default. Browse and one-click install more from the hosted marketplace, SHA256-verified, or install your own from a local ZIP.

🌐

Cluster Management

Multi-server node management from a single dashboard. Add remote ProxyStack instances, monitor health status, and push configuration to secondary nodes. Auto-refresh every 30 seconds. Enterprise license required.

📡

Node Control (Secure Remote Execution)

HMAC-paired mutual authentication between two ProxyStack instances - a one-time pairing code, then an AES-256-GCM-encrypted permanent signing key, then HMAC-SHA256-signed, replay-protected requests. A fixed allowlist of exactly 7 actions - no arbitrary command execution, ever. Two-sided RBAC and full audit logging on both ends. Lives inside the Cluster tab. Free tier.

🖥

Remote Access Manager (Self-Hosted RustDesk)

Your own private remote-desktop relay, installed and managed entirely through ProxyStack via Docker Compose (dry-run by default, pinned image tag, never latest). A dedicated 6-tab GUI view (Overview, Install, Devices, Clients, Security, Logs) and a full remote CLI command group. Real Security Center findings for downtime, exposed ports, and unmanaged remote-access tools already running on the machine. Free tier.

📱

Fleet Management

A unified device view joining Node Control's paired peers with Remote Access's device inventory into one grid, plus device groups. A real, per-peer opt-in interactive terminal (one command in, real output out - not a persistent shell) and file manager (deliberately unsandboxed, fully audited) ride Node Control's exact same authenticated channel, off by default until an operator explicitly enables them. Free tier.

💳

Licensing & Monetization

Built-in license activation on the Dashboard. Community (free), Pro, and Enterprise tiers with runtime feature gating. Stripe integration for checkout. License API (FastAPI) for validation, deactivation, and admin management. 14-day Pro trial included.

📋

Logs & Diagnostics

Centralized log viewer for Apache access/error logs and per-site logs. Real-time log tailing. Application settings management with theme toggle, auto-start configuration, and environment profile switching. All from dedicated Logs and Settings views.

How It Works

From download to production in under 5 minutes.

1

Download & Unzip

Download the portable ZIP (~138 MB). Extract to any folder. No installer needed.

2

Launch ProxyStack

Run ProxyStackGUI.exe. The modern dark-themed GUI opens with 25 sidebar views ready to use.

3

Add Your Sites

Configure domains, backends, and SSL certs from the Sites tab. Apache vhosts are auto-generated.

4

Start Apache

One click to start Apache. Your reverse proxy is live with TLS, security headers, and WAF protection.

25 Sidebar Views

Click any view to see what's inside. Every feature accessible from a modern dark-themed control panel.

01DashboardFree
02SitesFree
03AppsFree
04PostgreSQLFree
05DockerFree
06CertificatesFree
07MonitorFree
08SecurityFree
09ComplianceFree
10WAFFree
11ScannerFree
12Secrets VaultFree
13ReportsPro
14Zero TrustEnterprise
15SentinelAIPro
16TeamPro
17ObservabilityPro
18AdvancedFree
19ClusterEnterprise
20Security CenterEnterprise
21LogsFree
22SettingsFree
23Remote AccessFree
24AI RuntimeFree
25FleetFree

Dashboard

  • Start / Stop / Restart Apache
  • Service status cards (Apache, PostgreSQL, Docker)
  • Quick actions panel
  • Check for updates with SHA256 verification
  • License activation & 14-day Pro trial
  • Version info & system overview

Sites

  • Add / edit / remove domains
  • Reverse proxy target configuration
  • SSL certificate assignment
  • SPA fallback toggle
  • Per-path proxy routes (API + WebSocket)
  • Domain aliases
  • Auto-generate Apache vhost configs

Apps

  • Backend process manager
  • Sub-processes (e.g. Supabase + npm dev)
  • Auto-restart on crash
  • Health check monitoring
  • Per-app environment variables
  • Auto-accept npx/npm prompts

PostgreSQL

  • Start / stop / restart PostgreSQL
  • One-click auto-install with progress bar
  • Database list, create, drop
  • Built-in SQL query runner
  • Connection status monitoring
  • Portable binary (no Docker needed)

Docker

  • Container management (start, stop, restart, remove)
  • Docker Compose up/down
  • Image pull with progress
  • Container logs & inspect
  • 12 one-click container templates
  • Resource monitoring per container

Certificates

  • Let's Encrypt via bundled win-acme
  • Self-signed cert generation (OpenSSL)
  • Auto-detect cert paths by domain
  • Certificate expiry monitoring
  • Cert/key/chain file management

Monitor

  • Real-time CPU, RAM, disk metrics
  • Service health checks
  • Custom alert thresholds
  • Email & Slack notifications
  • 5-minute cooldown per service

Security

  • Security headers (HSTS, X-Frame, X-Content-Type, X-XSS) - enforced on both Nginx and Apache
  • IP whitelist / blacklist - enforced on both engines
  • REST API toggle (port 9090)
  • Auto-start with Windows
  • Environment profiles (dev/staging/prod)

Compliance (OWASP)

  • OWASP Top 10 2025 automated checks
  • Security score 0–100
  • Color-coded category cards (A01–A10)
  • Pass/fail breakdown per category
  • Export as CSV or TXT

Web Application Firewall

  • 14 built-in rules (SQLi, XSS, SSRF, etc.)
  • Custom rule editor with regex
  • Real inline blocking on both Nginx and Apache (403 before your site sees the request)
  • ModSecurity .conf export
  • Threat log (logs/waf-threats.jsonl) fed by real blocks plus a 60-second access-log scan

Security Scanner

  • Quick Scan (11 checks)
  • Full Scan (18 checks) — Pro
  • TLS, headers, permissions, secrets, ports
  • Severity: Critical / High / Medium / Low
  • Results saved to logs/security-scan.json

Secrets Vault

  • DPAPI-encrypted storage (Windows CurrentUser)
  • 8 categories (Database, API Key, OAuth, etc.)
  • 5-second auto-hide reveal
  • 30-second clipboard auto-clear
  • One-click 32-char rotation
  • Export as .env file

Compliance Reports Pro

  • SOC2 Type II (9 controls)
  • GDPR (6 articles)
  • PCI-DSS v4.0 (8 requirements)
  • HIPAA (5 safeguards)
  • "All Frameworks" mode (28 checks)
  • Export CSV / TXT

Zero Trust Enterprise

  • mTLS toggle with CA cert generation (RSA 4096)
  • Server cert generation (RSA 2048, auto-SAN)
  • Certificate auth policies (CN, OU, Issuer, Fingerprint, SAN)
  • Network segmentation zones (CIDR, port, direction)
  • Trust score 0–100
  • Export Apache .conf

SentinelAI Pro

  • Connect to SentinelAI dashboard
  • View agents & threat events
  • Launch Windows agent
  • 25+ real-time security monitors
  • 3-stage ML threat detection

Team Pro

  • Multi-user RBAC (Admin/Developer/Operator/Viewer)
  • Audit logging for all changes
  • .psxt template sharing (v1.2 bundles certs + files)
  • Slack webhook notifications
  • Up to 3 users (Pro), unlimited (Enterprise)

Observability Pro

  • Real request rate and error rate, parsed from live Nginx access logs
  • Latency percentiles (P50/P95/P99) shown when computable, honestly "n/a" otherwise - no per-request timing field in the access log yet
  • Recent request log

Advanced

  • Request/response rewriting and API gateway config editors (Classic UI - saved but not yet applied to live traffic)
  • Real per-site proxy caching (Nginx, via Sites tab)
  • Plugin Marketplace: 6 starter plugins + hosted marketplace (Pro to install)
  • Database console

Cluster Enterprise

  • Add/remove remote ProxyStack nodes
  • Health check all nodes (/api/status)
  • Push config to secondary nodes
  • Auto-refresh every 30 seconds
  • Node roles: Primary, Secondary, Standby, Worker
  • Activity log with timestamps
  • Optional VPN mesh join when adding a node (installs the ProxyStackVPN client on the remote node if needed) - cross-platform as of v14.17.0, Linux/macOS nodes included
  • Node Control (v14.21.0): HMAC-paired mutual authentication between instances, a fixed allowlisted action registry (node status, RustDesk compose status/up/down/restart/logs, security findings - no arbitrary command execution), and full audit logging on both ends

Security Center Enterprise

  • Unified status cards + threat timeline across WAF, SentinelAI, Cluster, Microsoft Defender, ClamAV, and Headscale VPN
  • Process Reputation: real Windows process-tree monitoring for every ProxyStack-managed app, with deterministic risk scoring
  • Reputation lookup: local allowlist/blocklist plus a real VirusTotal hash-only lookup (never uploads a file automatically)
  • Controlled sample submission to VirusTotal (explicit privacy warning + confirmation required)
  • Sandbox detonation: runs a flagged sample in an isolated, network-restricted, low-integrity-privilege temp environment (~15s) to observe real behavior
  • Policy enforcement: Kill, Quarantine, Block re-launch, Isolate network, or Require approval - manual or fully automatic once explicitly enabled
  • Every card is a real provider call - an unreachable or not-installed provider is shown honestly, never hidden

Remote Access

  • Self-hosted RustDesk Server (rustdesk/rustdesk-server, pinned version, never latest), managed via Docker Compose
  • Install/uninstall dry-run by default (--apply required to change anything)
  • 6 tabs: Overview, Install, Devices, Clients, Security, Logs
  • Start/Stop/Restart with live health, per-platform client setup instructions
  • Manual/CSV-importable device inventory, cross-checked against real paired Node Control peers
  • Backup-before-uninstall by default (--no-backup to opt out)

AI Runtime

  • Local model catalog - install and run local LLM + embedding backends (llama.cpp)
  • Curated Cloud/Runtime Packs: hand-picked starter recipes (Code Assistant, Private RAG Starter), SHA256-verified, never an open user-upload marketplace
  • RAG Knowledge Base - ingest a folder of documents (PDF, DOCX, Markdown, text), answer questions with citations back to the source
  • Read-only AI Operator Assistant - plain-language questions about sites, apps, deployments, and security findings, with visible sources; architecturally incapable of taking an action
  • Real Security Center findings for deployments bound to 0.0.0.0 (remote access), API-key/plaintext exposure, and runtime drift

Fleet

  • Unified device view joining Node Control's paired peers with Remote Access's device inventory - computed fresh on every call, no new persisted store
  • A paired peer with no matching inventory entry still appears as its own row - never invisible
  • Device groups - a single free-text tag for organizing the grid
  • Real interactive terminal (one command in, real stdout/stderr/exit code out) - request/response only, not a persistent shell, off by default per peer
  • Real, deliberately unsandboxed file manager (list/download/upload/delete) - broad by design, gated by explicit per-peer opt-in and full audit
  • Every session writes to a separate audit log with a real close signal and an honestly-labeled idle-timeout inference

Logs

  • Apache access & error logs
  • Per-site log files
  • Real-time log tailing
  • Log file viewer

Settings

  • Theme toggle (dark/light)
  • Auto-start Apache on launch
  • Auto-start with Windows
  • Environment profile switching
  • REST API configuration

Download ProxyStack

Unzip and run. No installation, no registry changes, no admin required. Built-in auto-updater keeps you current.

Lite Edition Windows GUI

~98 MB · v{{VERSION}}
Everything except PostgreSQL, ClamAV, and Headscale VPN - all three are one click away with the built-in "Download & Install" from the Docker/Security Center tabs whenever you need them. All 25 GUI views included.
Download Lite Edition

Cross-Platform CLI — 33 Commands, 5 Platforms

Single-binary, self-contained, no runtime needed. Docker, secure import, security scanning, backups, SentinelAI, monitoring — the portable control plane from the terminal.

Linux ARM64 v{{VERSION}}

~30 MB · .tar.gz
Raspberry Pi 4/5, AWS Graviton, Oracle Ampere, Apple Silicon VMs. Same 33 commands, same config format.
Download Linux ARM64

Windows x64 v{{VERSION}}

~43 MB · .zip · Includes SentinelAI Agent
Server Core, CI/CD pipelines, SSH management. Same proxystack.json as the GUI. Bundled SentinelAI security agent. Full feature parity.
Download Windows x64

macOS x64 (Intel) v{{VERSION}}

~31 MB · .tar.gz
Intel Macs (2012–2020). Manage Nginx/Apache, certs, Docker, security scans from Terminal.
Download macOS Intel

macOS ARM64 (Apple Silicon) v{{VERSION}}

~29 MB · .tar.gz
M1/M2/M3/M4 Macs. Native Apple Silicon binary — no Rosetta needed. Full CLI feature parity.
Download macOS Apple Silicon

All builds also available via GitHub CI/CD with automated tests

Linux Quick Start → One-liner install instructions

SentinelAI Security Agent

Cross-platform endpoint security agent — monitors processes, network, files, auth logs, cron jobs, and SSH keys. Reports to the SentinelAI dashboard with ML-powered threat detection.

Linux x64 Agent v2.0.0

~12 MB · .tar.gz · Single binary, no Python needed
Ubuntu, Debian, RHEL, Arch. 6 monitors: process, network, file integrity, auth log brute force, cron persistence, SSH key tampering. Connects to SentinelAI dashboard.
Download Linux x64 Agent

Windows x64 Agent v2.0.0

~11 MB · .zip · Single EXE, no Python needed
Windows 10/11, Server 2016+. Process, network, and file monitoring with Windows-specific registry, event log, and service detection. ML-powered analysis.
Download Windows x64 Agent

macOS and ARM64 agent builds coming soon · SentinelAI Dashboard →

VirusTotal Scan Results

Every release is scanned with 70+ antivirus engines. Transparency matters.

ProxyStackGUI.exe

0 / 72
security vendors flagged this file
CLEAN

ProxyStackGUI.dll

1 / 72
security vendors flagged this file
UNDER REVIEW

ProxyStackUpdater.exe

0 / 71
security vendors flagged this file
CLEAN

Scanned March 12, 2026 · v14.3.3 · SHA256 hashes verified

Latest scans: GUI EXE and Updater are clean; DLL has one vendor flag currently under review.

System Requirements

ProxyStack GUI runs on Windows with .NET 8. The CLI runs on Windows and Linux with zero dependencies.

💻
Windows 10/11 64-bit, version 1809 or later (GUI + CLI)
🐧
Linux x64 Ubuntu, Debian, RHEL, Arch, etc. (CLI only, self-contained)
.NET 8 Runtime Desktop runtime (auto-prompted if missing)
💾
300 MB Disk Space ~138 MB download + room for logs, certs, backups
🔌
Ports 80 & 443 For Apache reverse proxy (configurable)
🐳
Docker (Optional) Only needed for container management features
🌐
Internet (Optional) For Let's Encrypt, updates, and SentinelAI. Works offline otherwise.

Stay Updated

Get notified about new releases, security advisories, and tips.

Changelog

Recent updates and improvements across all releases.

v{{VERSION}} - Fleet Management: Unified Device View and a Real Interactive Terminal/File Manager

September 13, 2026
  • Fleet - A Unified View Across Node Control and Remote Access: the third and final piece of the Remote Access roadmap. A new "Fleet" sidebar view and proxystack fleet CLI group join Node Control's paired-peer registry with Remote Access's device inventory into one view, computed fresh on every call - a paired peer with no matching inventory entry still shows up as its own row, never invisible. Device groups add a single free-text tag for organizing the grid.
  • A Real Remote Terminal, Opt-In Per Device: proxystack fleet terminal exec and the GUI's Terminal dialog run one real command on a paired peer and return its real stdout/stderr/exit code - request/response only, not a persistent shell, no PTY. Off by default; an operator must explicitly enable it on the target device.
  • A Real Remote File Manager, Deliberately Unsandboxed: proxystack fleet files list/download/upload/delete and the GUI's Files dialog give real read/write/delete access to a paired peer's filesystem - broad by design, since the whole tier is opt-in and fully audited rather than a second sandboxed automation action wearing a file-manager costume.
  • Same Authentication, No New Trust Surface: both capabilities reuse Node Control's exact HMAC-signed, nonce-replay-protected channel - an unauthenticated caller gets the identical response whether a peer's flag is on or off, verified by a dedicated test on every new route. Every command and file operation writes to a separate audit log, with a real session-close signal and an honestly-labeled 5-minute idle-timeout inference rather than a fabricated clean exit.
  • Three Real Bugs Caught by a Whole-Branch Review Before Any of This Shipped: neither of the two independent Node Control HTTP listeners had ever bounded a request body - fixed with a shared incremental reader under a read timeout, so memory used tracks bytes actually received rather than a value an attacker's own header claims. The Fleet tab's "enable" toggle was presented backwards from what it actually grants - following its own on-screen instructions would have handed a remote peer access to the operator's own machine while claiming the opposite. And inferred session-timeout audit records were attributed to whichever peer happened to trigger the idle sweep, not the real owner of the swept session.

Version Archive

Release history. We recommend always using the latest version.

Version Date Highlights Full Lite
v{{VERSION}} (latest) Sep 14, 2026 Hardening follow-up. Fixed a real, currently-live install break in the AI Runtime Manager: LlamaCppInstaller was fetching a broken GitHub release (llama.cpp now marks every real binary-bearing build as a prerelease, which /releases/latest silently excludes), and had zero hash verification on the binary it downloaded and ran - both fixed, live-verified end-to-end with a real ~230MB build. Closed RBAC gaps on the AI Runtime GUI and CLI (Uninstall Pack, Delete Knowledge Base, Stop AI Deployment, Reveal Secret, ai stop, ai packs uninstall, deployments rollback) that had no admin-role check despite this app's established RBAC pattern. Extended a real UI-thread-disposal-race crash fix (previously only on one view) to the Classic UI and 13 other Views/Panels. Download Download